Legacy SSO Vulnerability Triggers Data Breach at Bromcom

AI-generated image · US National Wire
The UK education software provider discovered that a superseded sign-on service, kept active for an internal system, allowed unauthorized access to user email addresses.
UK education software provider Bromcom has notified customers of a personal data breach stemming from legacy single sign-on (SSO) registration functionality within its Communication Server environment. According to reporting from The Register, the company identified the incident on September 6 following reports of SSO access issues.
An unauthorized third party accessed and retrieved email addresses and limited information tied to SSO registrations. The compromised data included the identity of the provider used (such as Google or Microsoft), registration and last sign-in dates, and internal registration reference numbers and user IDs. Bromcom stated that the affected component did not contain authentication tokens or account passwords, and the breach did not grant access to external Microsoft or Google accounts.
Bromcom explained that the legacy functionality remained in production after being superseded because it was still being utilized by an internal system. The company has since withdrawn the functionality from production and is working with external forensic specialists to determine the full scope of the data involved. Bromcom confirmed that its school Management Information System (MIS)—which handles administration, attendance, behavior, and student data—was not compromised.
Bromcom provides information management tools for budgeting, HR, benchmarking, and timetabling to more than 390 multi-academy trusts and 5,000 schools. Its client list includes the Northern Ireland Education Authority, the Ministry of Defence, Warwickshire County Council, and Newport City Council.

